Skip to main content
QUIETLYTIC
Vulnerability

D-Link DIR-882 Vulnerability (CVE-2025-60698)

CVE-2025-60698 is a CVSS 7.3 unauthenticated command injection in D-Link DIR-882 router firmware, per VulnCheck alone.

CVE-2025-60698
Threat Level
HIGH
CVSS
7.3
Status
Active Exploitation
Confidence
Medium
Affected Products
D-Link DIR-882 (firmware DIR882A1_FW102B02)

CVE-2025-60698 carries a CVSS 3.1 base score of 7.3 against D-Link DIR-882 router firmware version DIR882A1_FW102B02. NVD classifies it as CWE-77 (Command Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated September 5, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2025-60698 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description, based on reverse-engineering research into the firmware’s prog.cgi and rc binaries, states that a user-supplied value from the router’s syslog remote-server configuration is stored in NVRAM without sanitization, then later retrieved and concatenated directly into a shell command executed by the firmware’s command-execution utility. NVD states an unauthenticated remote attacker can exploit this via specially crafted HTTP requests to the router’s web interface to execute arbitrary commands on the device.

Evidence and confidence

  • Medium confidence — the CVSS 7.3 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L), the CWE-77 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a published third-party firmware research writeup. The exploitation report traces to VulnCheck KEV alone.
  • High exploitation probability — FIRST’s EPSS model scores this CVE at 0.03929, an 89.8th percentile score as of our ingestion — notably high for a VulnCheck-only listing.

No field is in conflict between our two sources. Our source data does not carry a fixed-version field.

Why this matters

This is an unauthenticated command injection reachable through the router’s ordinary web management interface, which is often left internet-facing on consumer and small-office deployments. Combined with the near-90th-percentile EPSS score, this device model should be treated as an active target; owners of D-Link DIR-882 routers running the affected firmware should check D-Link’s security bulletin for an update and, in the interim, ensure the router’s web management interface is not exposed to the public internet.

Frequently Asked Questions

What is CVE-2025-60698? A CVSS 7.3 command injection vulnerability (CWE-77) in D-Link DIR-882 router firmware DIR882A1_FW102B02, allowing an unauthenticated remote attacker to execute arbitrary commands via crafted HTTP requests to the router’s web interface.

Is CVE-2025-60698 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 5, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated remote attacker.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our source data does not carry a fixed-version field. Consult D-Link’s own security bulletin for firmware update availability for the DIR-882 model.


Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2025-60698. Exploitation status and the September 5, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools